Regulatory Verification
Every requirement, answered with evidence.
We examine your website against every requirement that applies to it and record each one as met or not met, with the evidence and the clause behind it. A public page confirms the report was issued by STRASYS.
- Not a certificate
- Not legal advice
- Point in time
Three registers, kept apart on purpose: legal, standard and method.
A report that names only the law describes half of what it measured. Every criterion in this report sits in exactly one register, so you always know which findings could put you in front of a regulator and which could not.
Law in force
A statute or a directly applicable instrument. A finding here is a requirement that was met or not met, and the consequence exists outside this document.
GDPR, EAA, KVKKPublished specifications
Specifications from bodies that are not legislatures: schema.org, the IETF, Google, OWASP. Conformance is not compulsory; findings are reported as information.
schema.org, OWASPThe STRASYS checklist
Proprietary checks and commercial judgment about a website, labelled as such so they are never mistaken for a legal requirement.
STRASYS methodEight regimes, three regional packs.
The regimes in scope are chosen per engagement from where you operate and whom you serve. Each is cited by article or clause, with the authority, the effective date and the enforcement range on the criteria page of the report.
Packs: EU (GDPR, ePrivacy, EAA, AI Act, DSA), Türkiye (KVKK, ETBIS and 6563), Singapore (PDPA). Accessibility is verified against WCAG 2.2 AA through EN 301 549, the yardstick the European Accessibility Act enforces.
One document, every examination recorded.
The report is self-contained: criteria, requirement records, evidence index, document, sampling and system examinations, and the verification record. Around one hundred pages for a typical site.
Requirement register
Every applicable requirement with its verdict: met, not met, not applicable, outside method or outside scope. No partial verdicts; how badly a requirement is missed travels on the finding class.
- Clause reference for every row
- Finding class: observation, minor, major
- Neutral verdicts kept separate
Evidence index
What was fetched, when, from where, and its fingerprint. A finding without evidence is not issued.
- Timestamped retrievals
- SHA-256 per artefact
- Source and path recorded
Document examination
Contracts, notices and policies the web surface cannot reach are examined element by element, against the provision each element comes from.
- Document never stored, only its fingerprint
- Present, deficient or absent per element
- Provision cited per element
Sampling and systems
Record extracts and system settings the regulation requires, sampled and observed, with the selection method written down.
- Selection method disclosed
- Observation status per item
- Access route recorded
Declarations
What the obligated party declares about itself, recorded separately from what was examined, so the two are never confused.
- Declaration kinds enumerated
- Outcome per declaration
- Refusals recorded as such
Verification record
A public page, reachable by link or QR code, confirms the report id, the issue date, the issuer and whether the report has been withdrawn.
- No findings on the public page
- Withdrawal is visible
- Works without an account
Scoped, examined, reviewed, issued.
Scope and authorisation
You confirm the site, the regime packs and your written authorisation to examine it. Nothing is fetched before that.
Examination
Automatable checks run against the live site; content is read; documents, samples and systems you share are examined element by element.
Assessor review
Every verdict is entered by the assessor. AI drafts where it helps; it never decides a requirement.
Issue and verify
The report is issued as a numbered revision with a verification page. A later revision supersedes it and says so.
A statement of fact, not a certificate.
The boundaries are printed in the report and on this page, in the same words.
Built by the person who ran the operation.
20+ years in operations, 15+ in senior leadership, 10 with full P&L as GM and VP. The verification report follows the reporting discipline he worked under for two decades.
About the founder →Scoped per site and pack, quoted in writing.
The price depends on the size of the site, the regime packs and whether documents, samples and systems are in scope. You receive a written scope and a written price after one call.
- Criteria page with authority, effective date, enforcement range
- Evidence index and public verification page
- Document, sampling and system examinations where in scope
- Bilingual: English or Turkish
- Infrastructure, security, privacy and consent
- SEO, structured data, AI visibility
- Forms, analytics, performance, accessibility
- One-time, credited toward a build
Answered before you ask.
Is this a certificate?
No. It is a third-party verification report: a statement of what was examined and whether each requirement was met. It is not a certificate of conformity and STRASYS is not an accredited certification or inspection body.
Is it legal advice?
No. The report records facts against published requirements. What to do about a finding in your jurisdiction is a question for your counsel; the report gives them the evidence.
Which laws are covered?
GDPR, the ePrivacy Directive, the European Accessibility Act with EN 301 549 and WCAG 2.2 AA, the AI Act transparency article, the Digital Services Act, KVKK, ETBIS with the Turkish E-Commerce Law, and the Singapore PDPA, selected per engagement as EU, Türkiye and Singapore packs.
How is the site examined?
Automatable checks run against the publicly reachable site during a recorded assessment period; content is read; documents, record extracts and system settings you share are examined and only their fingerprint is kept. No active security testing is performed.
Who does the work?
The founder of STRASYS, as a single assessor. The report says so, and it says that no independent review step is claimed.
How does someone check that a report is genuine?
Every issued report carries a verification link and a QR code. The public page confirms the report id, issue date and issuer, and shows whether the report has been withdrawn. It shows no findings.